{"id":"CVE-2026-42501","title":"cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)","summary":"A flaw was found in the Go command (`cmd/go`). A malicious module proxy can exploit this vulnerability by bypassing the validation of module checksums. This allows the proxy to serve altered versions of the Go toolchain, which the `go` com…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","cvssSource":"vendor","cwe":"CWE-347","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream (v. 8)","affected":["exploit_intelligence","multicluster_engine_for_kubernetes","openshift_api_for_data_protection","openshift_service_mesh 2","openshift_service_mesh 3","advanced_cluster_management_for_kubernetes 2","enterprise_linux_ai_rhel_ai 3","openshift_container_platform 4","openshift_virtualization 4","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","hardened_images"],"patched":["enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","hardened_images"],"published":"2026-05-07","updated":"2026-09-09","sourceUpdated":"2026-09-09T00:37:19+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42501.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42501.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-42501"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467810"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-42501"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42501"},{"url":"https://go.dev/cl/775321"},{"url":"https://go.dev/issue/79070"},{"url":"https://groups.google.com/g/golang-announce/c/qcCIEXso47M"},{"url":"https://pkg.go.dev/vuln/GO-2026-4984"},{"url":"https://access.redhat.com/errata/RHSA-2026:49702"},{"url":"https://access.redhat.com/errata/RHSA-2026:22120"},{"url":"https://access.redhat.com/errata/RHSA-2026:22112"},{"url":"https://access.redhat.com/errata/RHSA-2026:61253"},{"url":"https://access.redhat.com/errata/RHSA-2026:57649"},{"url":"https://access.redhat.com/errata/RHSA-2026:49712"},{"url":"https://access.redhat.com/errata/RHSA-2026:22121"},{"url":"https://access.redhat.com/errata/RHSA-2026:32987"},{"url":"https://access.redhat.com/errata/RHSA-2026:23262"},{"url":"https://access.redhat.com/errata/RHSA-2026:23264"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00231,"epssPercentile":0.14136,"aliases":["GO-2026-4984","BIT-golang-2026-42501"],"ecosystem":"go","ingestedAt":"2026-08-26T19:27:02.550Z","slug":"CVE-2026-42501","body":"## Overview\n\nA flaw was found in the Go command (`cmd/go`). A malicious module proxy can exploit this vulnerability by bypassing the validation of module checksums. This allows the proxy to serve altered versions of the Go toolchain, which the `go` command may then download and execute without proper verification. This can lead to the execution of untrusted code, compromising the integrity of the Go development environment.\n\n## Vendor advisories\n\n- **RHSA-2026:49702** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49702)\n- **RHSA-2026:22120** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22120)\n- **RHSA-2026:22112** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22112)\n- **RHSA-2026:61253** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61253)\n- **RHSA-2026:57649** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57649)\n- **RHSA-2026:49712** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49712)\n- **RHSA-2026:22121** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22121)\n- **RHSA-2026:32987** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:32987)\n- **RHSA-2026:23262** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23262)\n- **RHSA-2026:23264** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23264)\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Multicluster Engine for Kubernetes, OpenShift API for Data Protection, OpenShift Service Mesh 2, OpenShift Service Mesh 3, Red Hat Advanced Cluster Management for Kubernetes 2, … · no fix planned: Exploit Intelligence, Multicluster Engine for Kubernetes, OpenShift API for Data Protection, OpenShift Service Mesh 2, … · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42501.json)\n\n**cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy** — rated Moderate by Red Hat. Released 2026-05-07, updated 2026-09-09.\n\nAffected:\n\n- Exploit Intelligence\n- Multicluster Engine for Kubernetes\n- OpenShift API for Data Protection\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Virtualization 4\n\nFixed:\n\n- Red Hat Enterprise Linux AppStream EUS (v. 10.0)\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream E4S (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Hardened Images\n\nNo fix planned:\n\n- Exploit Intelligence\n- Multicluster Engine for Kubernetes\n- OpenShift API for Data Protection\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Virtualization 4\n- Red Hat Advanced Cluster Management for Kubernetes 2\n\nNot affected:\n\n- Multicluster Engine for Kubernetes\n- Red Hat Advanced Cluster Management for Kubernetes 2\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:49702\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22120\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22112\n\nWorkarounds / mitigations:\n\n- To verify the integrity of Go module dependencies and detect potential tampering by a malicious proxy, users can revalidate all dependencies of the current module. This process involves removing the existing `go.sum` file and then re-generating and verifying module checksums.\n\nExecute the following commands in your module's root directory:\n```bash\nrm go.sum\ngo mod tidy\ngo mod verify\n```\nThis operation will re-download and re-verify all module dependencies. Be aware that this may affect your loc…\n\n## Package advisory (CVE-2026-42501)\n\nAffected packages:\n\n- `toolchain >= 1.26.0-0, < 1.26.3`\n\nPatched in:\n\n- `toolchain 1.26.3`\n\nSource: https://osv.dev/vulnerability/GO-2026-4984","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":201642,"id":"CVE-2026-42501","ts":1789399580540,"field":"cvss","old":null,"new":"5.3"},{"seq":201641,"id":"CVE-2026-42501","ts":1789399580540,"field":"severity","old":"none","new":"medium"},{"seq":200374,"id":"CVE-2026-42501","ts":1789397179835,"field":"cvss","old":"5.3","new":null},{"seq":200373,"id":"CVE-2026-42501","ts":1789397179835,"field":"severity","old":"medium","new":"none"},{"seq":198298,"id":"CVE-2026-42501","ts":1789391809732,"field":"cvss","old":null,"new":"5.3"},{"seq":198297,"id":"CVE-2026-42501","ts":1789391809732,"field":"severity","old":"none","new":"medium"},{"seq":196091,"id":"CVE-2026-42501","ts":1789383455063,"field":"cvss","old":"5.3","new":null},{"seq":196090,"id":"CVE-2026-42501","ts":1789383455063,"field":"severity","old":"medium","new":"none"},{"seq":195020,"id":"CVE-2026-42501","ts":1789380352502,"field":"cvss","old":null,"new":"5.3"},{"seq":195019,"id":"CVE-2026-42501","ts":1789380352502,"field":"severity","old":"none","new":"medium"},{"seq":193807,"id":"CVE-2026-42501","ts":1789378319363,"field":"cvss","old":"5.3","new":null},{"seq":193806,"id":"CVE-2026-42501","ts":1789378319363,"field":"severity","old":"medium","new":"none"},{"seq":192594,"id":"CVE-2026-42501","ts":1789376298119,"field":"cvss","old":null,"new":"5.3"},{"seq":192593,"id":"CVE-2026-42501","ts":1789376298119,"field":"severity","old":"none","new":"medium"},{"seq":191381,"id":"CVE-2026-42501","ts":1789373210623,"field":"cvss","old":"5.3","new":null},{"seq":191380,"id":"CVE-2026-42501","ts":1789373210623,"field":"severity","old":"medium","new":"none"},{"seq":190166,"id":"CVE-2026-42501","ts":1789369191120,"field":"cvss","old":null,"new":"5.3"},{"seq":190165,"id":"CVE-2026-42501","ts":1789369191120,"field":"severity","old":"none","new":"medium"},{"seq":188953,"id":"CVE-2026-42501","ts":1789368072915,"field":"cvss","old":"5.3","new":null},{"seq":188952,"id":"CVE-2026-42501","ts":1789368072915,"field":"severity","old":"medium","new":"none"},{"seq":187736,"id":"CVE-2026-42501","ts":1789365047313,"field":"cvss","old":null,"new":"5.3"},{"seq":187735,"id":"CVE-2026-42501","ts":1789365047313,"field":"severity","old":"none","new":"medium"},{"seq":186523,"id":"CVE-2026-42501","ts":1789363065719,"field":"cvss","old":"5.3","new":null},{"seq":186522,"id":"CVE-2026-42501","ts":1789363065719,"field":"severity","old":"medium","new":"none"},{"seq":185309,"id":"CVE-2026-42501","ts":1789361004757,"field":"cvss","old":null,"new":"5.3"},{"seq":185308,"id":"CVE-2026-42501","ts":1789361004757,"field":"severity","old":"none","new":"medium"},{"seq":184096,"id":"CVE-2026-42501","ts":1789357991548,"field":"cvss","old":"5.3","new":null},{"seq":184095,"id":"CVE-2026-42501","ts":1789357991548,"field":"severity","old":"medium","new":"none"},{"seq":182348,"id":"CVE-2026-42501","ts":1789354144358,"field":"cvss","old":null,"new":"5.3"},{"seq":182347,"id":"CVE-2026-42501","ts":1789354144358,"field":"severity","old":"none","new":"medium"},{"seq":181141,"id":"CVE-2026-42501","ts":1789352987882,"field":"cvss","old":"5.3","new":null},{"seq":181140,"id":"CVE-2026-42501","ts":1789352987882,"field":"severity","old":"medium","new":"none"},{"seq":179934,"id":"CVE-2026-42501","ts":1789350054173,"field":"cvss","old":null,"new":"5.3"},{"seq":179933,"id":"CVE-2026-42501","ts":1789350054173,"field":"severity","old":"none","new":"medium"},{"seq":178727,"id":"CVE-2026-42501","ts":1789347904110,"field":"cvss","old":"5.3","new":null},{"seq":178726,"id":"CVE-2026-42501","ts":1789347904110,"field":"severity","old":"medium","new":"none"},{"seq":177520,"id":"CVE-2026-42501","ts":1789346207073,"field":"cvss","old":null,"new":"5.3"},{"seq":177519,"id":"CVE-2026-42501","ts":1789346207073,"field":"severity","old":"none","new":"medium"},{"seq":176313,"id":"CVE-2026-42501","ts":1789342810060,"field":"cvss","old":"5.3","new":null},{"seq":176312,"id":"CVE-2026-42501","ts":1789342810060,"field":"severity","old":"medium","new":"none"},{"seq":175767,"id":"CVE-2026-42501","ts":1789338593793,"field":"cvss","old":null,"new":"5.3"},{"seq":175766,"id":"CVE-2026-42501","ts":1789338593793,"field":"severity","old":"none","new":"medium"},{"seq":175637,"id":"CVE-2026-42501","ts":1789338435252,"field":"cvss","old":"5.3","new":null},{"seq":175636,"id":"CVE-2026-42501","ts":1789338435252,"field":"severity","old":"medium","new":"none"},{"seq":174432,"id":"CVE-2026-42501","ts":1789334637982,"field":"cvss","old":null,"new":"5.3"},{"seq":174431,"id":"CVE-2026-42501","ts":1789334637982,"field":"severity","old":"none","new":"medium"},{"seq":173227,"id":"CVE-2026-42501","ts":1789333301530,"field":"cvss","old":"5.3","new":null},{"seq":173226,"id":"CVE-2026-42501","ts":1789333301530,"field":"severity","old":"medium","new":"none"},{"seq":172041,"id":"CVE-2026-42501","ts":1789330927730,"field":"cvss","old":null,"new":"5.3"},{"seq":172040,"id":"CVE-2026-42501","ts":1789330927730,"field":"severity","old":"none","new":"medium"}]}